wzp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from d26yaxxlnmhaem.cloudfront.net and multiple other hosts.
MD5:
0311f23a4fb750f342953a8efb03b028

SHA-1:
4a505f254210dc7267bdc82c220bbd3c79cac37d

SHA-256:
1d805d035ffceaf0272400c2762650cecfb0c6dc40fc3916f3cd84a1431122e8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/8/2025 5:12:20 PM UTC  (today)

File size:
2.9 MB (3,039,334 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wzp.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:EOzZbs2adyWOI/rFLC6jOQIifT4YW4movDZz5LscfWH1x0QCE2cKV02WoVWFUNGq:G6WOqPAifT4YTmAZCcOQpE/KdWX2NGYX

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, 53, 9B, 84, FA, 7B, 3A, 74, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, 7A, 2A, 18, BC, BB, F5, 4F, BA, 59, 07, 00, 40, 56, 18, E2, A0, CC, B5, 24, 82, 28, A1, 7A, 81, 99, 09, 91, 39, 23, F6, 24, F4, 21, 5A, 4D, 6D, 53, F5, 65, DA, BE, 0A, E1, EB, CB, F7, B2, 8B, 39, E3, 6D, 66, 8F, 27, 7D, 07, BF, 14, 1A, 5A, 34, E8, 1F, 8F, 3F, 0C, A3, DF, 35, BF, F5, C2, 4A, D2, A4, 25, 36, F6, 01, F6, 7D, 6F, 90, FD, 59, 29, 91, 13, 1B, 95, D3, A8, 3D, 6C, 2B, 74, CE, A8, 2A, 5B...
 
[+]

Entropy:
7.9999  (probably packed)

The file wzp.exe has been seen being distributed by the following 6 URLs.

http://d26yaxxlnmhaem.cloudfront.net/Public/softs/wzp/2.2.60/.../wzp.exe

http://113.171.224.208/.../wzp.exe

http://113.171.224.245/.../wzp.exe

http://113.171.224.170/.../wzp.exe

Scan wzp.exe - Powered by Reason Core Security